Skip to content
Noroxi

cryptocat project records

17 published records for vendor cryptocat project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

17 records
  • Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    cryptocat project · cryptocatNov 4, 2019

  • Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview

    CriticalCVSS 9.8No exploitEPSS 4%

    cryptocat project · cryptocatNov 4, 2019

  • Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness

    CriticalCVSS 9.8No exploitEPSS 2%

    cryptocat project · cryptocatNov 4, 2019

  • CVE-2013-4108
    39Monitor

    Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.

    CriticalCVSS 9.8No exploitEPSS 2%

    cryptocat project · cryptocatNov 14, 2019

  • CVE-2013-4102
    37Monitor

    Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness

    CriticalCVSS 9.1No exploitEPSS 2%

    cryptocat project · cryptocatNov 4, 2019

  • CVE-2013-2261
    33Monitor

    Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure

    HighCVSS 7.5Proof of conceptEPSS 12%

    cryptocat project · cryptocatNov 4, 2019

  • CVE-2013-4100
    31Monitor

    Cryptocat before 2.0.22 has Remote Denial of Service via username

    HighCVSS 7.5No exploitEPSS 2%

    cryptocat project · cryptocatNov 4, 2019

  • CVE-2013-2257
    31Monitor

    Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness

    HighCVSS 7.5No exploitEPSS 2%

    cryptocat project · cryptocatNov 4, 2019

  • CVE-2013-2262
    31Monitor

    Cryptocat strophe.js before 2.0.22 has information disclosure

    HighCVSS 7.5No exploitEPSS 2%

    cryptocat project · cryptocatNov 4, 2019

  • CVE-2013-4105
    30Monitor

    Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure

    HighCVSS 7.5No exploitEPSS 1%

    cryptocat project · cryptocatNov 4, 2019

  • CVE-2013-4104
    30Monitor

    Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol

    HighCVSS 7.5No exploitEPSS 1%

    cryptocat project · cryptocatNov 4, 2019

  • CVE-2013-4109
    25Monitor

    An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.

    MediumCVSS 6.1No exploitEPSS 2%

    cryptocat project · cryptocatNov 14, 2019

  • CVE-2013-4106
    24Monitor

    A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.

    MediumCVSS 6.1No exploitEPSS 1%

    cryptocat project · cryptocatNov 14, 2019

  • CVE-2013-4107
    24Monitor

    Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    cryptocat project · cryptocatNov 5, 2019

  • CVE-2013-4110
    22Monitor

    Cryptocat has an Unspecified Chat Participant User List Disclosure

    MediumCVSS 5.3No exploitEPSS 2%

    cryptocat project · cryptocatNov 5, 2019

  • CVE-2013-2258
    21Monitor

    Cryptocat before 2.0.22 has Nickname User Impersonation

    MediumCVSS 5.3No exploitEPSS 1%

    cryptocat project · cryptocatNov 4, 2019

  • CVE-2013-4101
    21Monitor

    Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness

    MediumCVSS 5.3No exploitEPSS 1%

    cryptocat project · cryptocatNov 4, 2019